针对少样本生物特征模型的隐私攻击:融合多模型输出
计算机视觉与模式识别
2022-09-23 v1 密码学与安全
摘要
认证系统易受模型反演攻击,攻击者可借此逼近目标机器学习模型的逆。生物特征模型是此类攻击的主要目标,因为反演生物特征模型可使攻击者生成逼真的生物特征输入以欺骗生物特征认证系统。成功实施模型反演攻击的主要限制之一在于所需训练数据量。本工作中,我们关注虹膜与人脸生物特征系统,提出一种大幅减少所需训练数据量的新技术。通过利用多个模型的输出,我们得以使用仅为 Ahmad 与 Fuller(IJCB 2020)虹膜数据训练集规模 1/10、仅为 Mai 等人(Pattern Analysis and Machine Intelligence 2019)人脸数据训练集规模 1/1000 的训练集实施模型反演攻击。我们将这一新攻击技术称为带对齐损失的结构化随机。我们的攻击为黑盒攻击,无需知晓目标神经网络的权重,仅需输出向量的维度与数值。为展示对齐损失的通用性,我们将该攻击框架应用于生物特征数据上的成员推断任务(Shokri 等人,IEEE S&P 2017)。对于虹膜,针对分类网络的成员推断攻击准确率由 52% 提升至 62%。
引用
@article{arxiv.2209.11020,
title = {Privacy Attacks Against Biometric Models with Fewer Samples: Incorporating the Output of Multiple Models},
author = {Sohaib Ahmad and Benjamin Fuller and Kaleel Mahmood},
journal= {arXiv preprint arXiv:2209.11020},
year = {2022}
}
备注
This is a major revision of a paper titled "Inverting Biometric Models with Fewer Samples: Incorporating the Output of Multiple Models" by the same authors that appears at IJCB 2022